With the launch of PAN-OS 8.0, TACACS has been enhanced to use Authorization from the TACACS server. Before PAN-OS 8.0, TACACS was limited to Authentication only. If you wanted to authenticate against a TACACS server to log in to the GUI or CLI, you had to create the same admin accounts on the Palo Alto Networks device, which doesn't scale well and is additional overhead, especially in large or dynamic environments. See the improvement with PAN-OS 8.0.